Bitbucket
Vendor:
First CVE: Apr 10, 2017 · Active for 9 years
20
Total CVEs
More Total CVEs than 94% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
5.0%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Bitbucket over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2017
9 years ago
Most Recent CVE
Nov 17, 2022
1,347 days ago
CVE Severity & Scoring
Bitbucket20 CVEs
40%
35%
25%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (90.0%)
High2 (10.0%)
Unknown0 (0.0%)
User Interaction
None18 (90.0%)
Unknown0 (0.0%)
Required2 (10.0%)
Privileges Required
Low12 (60.0%)
High1 (5.0%)
None7 (35.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36804HIGH Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21 | Aug 25, 2022 | 8.8 | 99 | YES | YES |
CVE-2022-43781CRITICAL There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this i | Nov 17, 2022 | 9.8 | 88 | NO | YES |
CVE-2022-26136CRITICAL A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which f | Jul 20, 2022 | 9.8 | 34 | NO | NO |
CVE-2019-15000CRITICAL The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 | Sep 19, 2019 | 9.8 | 34 | NO | NO |
CVE-2018-5225CRITICAL In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5. | Mar 22, 2018 | 9.9 | 33 | NO | NO |
CVE-2019-3397CRITICAL Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), | Jun 3, 2019 | 9.1 | 32 | NO | NO |
CVE-2022-26137HIGH A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests o | Jul 20, 2022 | 8.8 | 29 | NO | NO |
CVE-2019-20097HIGH Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before | Jan 15, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-15012HIGH Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, fr | Jan 15, 2020 | 8.8 | 26 | NO | NO |
CVE-2019-15010HIGH Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from vers | Jan 15, 2020 | 8.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
1 CVE
5.0% of CVEs· 97th percentile
Metasploit
2 CVEs
10.0% of CVEs· 97th percentile
Nuclei
1 CVE
5.0% of CVEs· 97th percentile
ExploitDB
1 CVE
5.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Bitbucket
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.3.0 | 1 | 8.8 | 99.1% | 1 | 1 |
| 8.1.0 | 2 | 9.3 | 3.6% | 0 | 0 |
| 8.0.0 | 2 | 9.3 | 3.6% | 0 | 0 |
| 5.5.6 | 1 | 6.5 | 1.3% | 0 | 0 |
| 5.5.5 | 1 | 6.5 | 1.3% | 0 | 0 |
| 5.5.4 | 1 | 6.5 | 1.3% | 0 | 0 |
| 5.5.3 | 1 | 6.5 | 1.3% | 0 | 0 |
| 5.5.2 | 1 | 6.5 | 1.3% | 0 | 0 |
| 5.5.0 | 1 | 6.5 | 1.3% | 0 | 0 |